Risky to adopt: the package has had no release in about seven years and no repository commits in about six years. Its small, focused codebase, MIT license, matching organization-backed repository, and minimal dependency footprint reduce complexity but do not offset the apparent abandonment risk.
43%
Total Score
50
100
69
83
The latest release was published in June 2019, with no releases in the last 12 months. That long release gap is a substantial maintenance concern for a Symfony integration package.
The repository recorded zero commits and zero active maintainers in the last three months, following a last push in September 2020. This strongly suggests that compatibility and bug fixes may no longer be maintained.
The package includes a README and publishes GitHub releases, but the README is only 84 characters and both the package and repository report no tests. Missing tests materially reduce confidence in an old framework integration.
The repository has zero stars and zero forks, with only three watchers. Low adoption is supporting evidence of limited external scrutiny, though popularity alone is not decisive.
Composer is used as the build tool, but no security scanning tools are present. The simple package structure limits the impact, yet the absence of automated security checks is a hygiene weakness.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.